RPS Defense completed its CMMC Level 2 assessment with every requirement met and every assessment objective verified — no conditional status, no remediation clock. The environment behind the score: Essendis's turnkey Secure Enclave on Microsoft 365 GCC High, deployed with the security and compliance program to run it. Here's how the engagement ran.
See how they did itRPS Defense — Remotely Piloted Solutions, LLC — is a Dallas-based defense services company: manned and unmanned aircraft operations, aircrew and UAS training, intelligence support, and flight test for the Department of Defense and its primes. Its everyday work product — mission data, training curricula, technical data tied to DoD aviation programs — is exactly the Controlled Unclassified Information that CMMC Level 2 exists to protect. A conditional pass (88 or more requirements met, with a 180-day clock to close the rest) was technically available. RPS's leadership set the target at the top: everything met, first time. Rather than re-engineer its entire network, RPS deployed the Essendis Secure Enclave — a turnkey CMMC Level 2 boundary on Microsoft 365 GCC High — and scoped the assessment to it.
Client: RPS Defense — manned & unmanned aircraft services
Standard: NIST SP 800-171 R2 · 110 requirements · 320 objectives
Solution: turnkey Essendis Secure Enclave on Microsoft 365 GCC High
Assessor: accredited C3PAO · runway: roughly 7 months
Result: 110/110 — Final Level 2 status
The plan was built backwards from a simple rule: nothing the C3PAO asks for should be created, found, or explained for the first time in front of an assessor.
Mapped where CUI actually flowed, drew the enclave boundary around it, and scored the starting position against all 110 requirements — honestly, including the ugly parts.
Stood up the turnkey Secure Enclave on Microsoft 365 GCC High with the technical controls pre-configured, then laid down the security and compliance program around it — policies, procedures, and a System Security Plan that matched the environment as deployed. Every one of the 320 assessment objectives got an owner and an evidence artifact.
Before the C3PAO arrived, Essendis's advisory practice pressure-tested the program — walking the controls, pulling the evidence, and asking the hard questions first.
The C3PAO examined, interviewed, and tested. The RPS team fielded the questions, because by then the answers were theirs.
A Level 2 assessment walks all fourteen NIST SP 800-171 control families, verifying each of the 320 assessment objectives behind the 110 requirements — all of it scoped to the Secure Enclave. Here's how RPS Defense scored.
Access Control — 22/22 met
Awareness & Training — 3/3 met
Audit & Accountability — 9/9 met
Configuration Management — 9/9 met
Identification & Authentication — 11/11 met
Incident Response — 3/3 met
Maintenance — 6/6 met
Media Protection — 9/9 met
Personnel Security — 2/2 met
Physical Protection — 6/6 met
Risk Assessment — 3/3 met
Security Assessment — 4/4 met
System & Comms Protection — 16/16 met
System & Info Integrity — 7/7 met
— RPS Defense, Program Manager
The Secure Enclave arrived on Microsoft 365 GCC High with the technical controls already configured and documented — remediation started from a hardened baseline, not a blank page.
Every one of NIST SP 800-171's 110 controls was assessed against its own objectives, not just the control title.
The System Security Plan described the environment as built, not as originally scoped, so nothing needed explaining away.
The enclave wasn't a general-purpose environment retrofitted to a standard. It was designed from day one as a CMMC Level 2 boundary for defense contractors — so every control mapped cleanly to how the environment actually runs.